home/glossary/external system service

external system service

nounid 163436·updated Aug 30, 2026
verified

A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by but not a part of the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

MWE

Source

document
NIST Special Publication 800 NIST SP 800-171r3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
publisher
Ron Ross Victoria Pillitteri
found in
glossary section
discovery
AuthoritativeImport

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems9 citations · 9 defined by this document · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.16.0303.16.03.a03.16.03.b03.16.03.c03.16.03.c3.2.2 ¶ 453.2.2 ¶ 483.2.2 ¶ 503.2.2 ¶ 51

Classifications

Entity Type

System85%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated78%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

No variants recorded
This term has no surface-form variants in the lexicon yet, so it tags only its canonical form.

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · glossary
A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by but not a part of the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by but not a part of the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.